Init parameterSecurity & auditing
SEC_MAX_FAILED_LOGIN_ATTEMPTS
What it controls
Failed attempts on one connection before the server drops it.
Know this before you change it
This drops the connection; it doesn't lock the account. Account locking comes from the profile's FAILED_LOGIN_ATTEMPTS.
Default: 3
Check and change it
1-- Current value on every instance2SELECT inst_id, name, value, isdefault, ismodified3FROM gv$parameter4WHERE name = 'sec_max_failed_login_attempts';5 6-- Value stored in the spfile7SELECT sid, value FROM v$spparameter WHERE name = 'sec_max_failed_login_attempts' AND isspecified = 'TRUE';8 9-- Static: saved in the spfile, takes effect after a restart10ALTER SYSTEM SET sec_max_failed_login_attempts = 3 SCOPE = SPFILE SID = '*';11 12-- Remove it from the spfile to go back to the default at the next restart13ALTER SYSTEM RESET sec_max_failed_login_attempts SCOPE = SPFILE SID = '*';Related scripts
- Failed logins in the last 24 hoursFrom the unified audit trail, which records failed logons by default through the ORA_LOGON_FAILURES policy. Return code 1017 is a wrong password;…
- Password profile settingsPassword rules for each profile: lifetime, reuse, failed attempts and the verify function. Shows why an account locked or expired.
Open in the parameter referenceOracle's reference
More in Security & auditing
- AUDIT_TRAILWhere traditional auditing records go.
- AUDIT_SYS_OPERATIONSAudits top-level statements run as SYS, SYSDBA and SYSOPER to OS files.
- AUDIT_FILE_DESTDirectory for OS audit files, including SYS audit records.
- REMOTE_LOGIN_PASSWORDFILEWhether a password file is used for remote SYSDBA connections.